Introduction
The EU AI Act is the European Union’s first comprehensive AI regulation, built on a risk-based approach that classifies AI systems from minimal risk through to prohibited. It applies to anyone who builds, deploys, or imports AI systems whose outputs touch the EU market, regardless of where the organization is headquartered.
In July 2026, the AI Omnibus significantly reshaped the AI Act timeline. Some compliance deadlines were pushed back by more than a year, while others remained firmly in place. For organizations that had been sprinting toward an August 2026 high-risk deadline, the ground shifted beneath their feet.
This article focuses on what changed in the timeline and how you should adjust your preparation plan. It is written from the perspective of Pandectes, a privacy and compliance SaaS provider for Shopify stores, with a focus on practical implications for digital businesses and e-commerce. Expect concrete dates from 2024 through 2028, specific compliance deadlines, and actionable steps to strengthen AI governance, AI literacy, and risk management.
Original vs Updated EU AI Act Timeline at a Glance
The EU AI Act follows a phased implementation roadmap from 2024 through 2028. Understanding which dates moved and which held firm is critical for resource planning. Here is how the original and updated timelines compare.
Original enforcement path:
- 12 July 2024: AI Act published in the Official Journal of the European Union
- 1 August 2024: the EU AI Act officially entered into force
- 2 February 2025: prohibited AI practices, core definitions, and AI literacy obligations apply
- 2 August 2025: general purpose AI (GPAI) governance rules and national authorities’ obligations begin
- 2 August 2026 (original): high-risk AI obligations, transparency obligations, and enforcement mechanisms were all set to kick in
How the AI Omnibus changed the picture:
- Standalone high-risk AI systems under Annex III: deadline moved from 2 August 2026 to 2 December 2027
- High-risk AI systems embedded in regulated products under Annex I (safety components, medical devices, machinery regulation): deadline extended to 2 August 2028
- Core user transparency duties became enforceable on August 2, 2026, with transitional marking requirements by 2 December 2026
- New prohibited AI practices (CSAM, non-consensual intimate imagery) apply from 2 December 2026
- National AI regulatory sandboxes must be established by 2 August 2027
The risk-based approach of the AI Act underpins this phased timeline: earlier application targets the most harmful or systemic risks, while high-risk obligations get more runway for standardization and infrastructure development across member states.
What Is Already in Force: 2024-2025 Obligations You Cannot Ignore
Several obligations are already legally binding. Organizations cannot treat the postponed high-risk deadlines as a blanket reprieve.
August 2024: The regulation entered into force. By November 2024, member states were expected to list the national authorities responsible for protecting fundamental rights in the context of AI systems.
2 February 2025: The first provisions of the AI Act became applicable on this date. Prohibitions on unacceptable-risk AI practices took full effect on February 2, 2025. These cover subliminal manipulation, exploitation of vulnerabilities, social scoring by public authorities, real-time remote biometric identification in public spaces (with narrow exceptions), and predictive policing. AI literacy obligations also took effect, requiring persons dealing with AI systems, both providers and deployers, to support AI literacy development among staff and users.
2 August 2025: General purpose AI governance rules became operational on August 2, 2025. Providers of general-purpose AI models must now maintain technical documentation, disclose summaries of training data, and comply with copyright policies. General-purpose AI GPAI models with systemic risk carry additional burdens: incident reporting, adversarial testing, and notification to the AI Office.
AI literacy measures for staff are required for compliance with the EU AI Act, and this obligation is already in effect. If your team uses AI technologies, whether chatbots, content generators, or analytics tools, they should understand what these systems do, their limitations, and how to escalate concerns.
Postponed Deadlines for High-Risk AI: December 2027 and August 2028
This is the most consequential change from the AI Omnibus for many businesses. Here are the specific dates and what they mean in practice.
High-risk systems must comply by 2 December 2027. This applies to standalone systems classified under Annex III, including AI used in employment decisions, credit scoring, education assessment, access to critical infrastructure, and essential public services. The original deadline was 2 August 2026; organizations now have roughly 16 additional months.
AI systems under Annex I must comply by 2 August 2028. High-risk AI systems embedded in regulated products face a compliance deadline of 2 August 2028. These include safety components of machinery (under the machinery regulation), medical devices, and other product safety regimes. This is a full two-year extension from the original date.
These shifts do not remove obligations. Providers and deployers will still need to implement:
- Risk management systems and quality management processes
- Data governance and documentation of training data quality
- Human oversight mechanisms
- Post-market monitoring plan procedures
- Conformity assessment and registration in the EU database
High-risk AI system obligations are postponed to December 2027 and August 2028, but foundational work, system inventories, risk assessments, and documentation templates should be underway now. Retrofitting governance weeks before a deadline is far more expensive and error-prone than building incrementally.

A Google-Approved Consent Platform for Shopify
Pandectes is an official Google Certified Consent Management Platform and is fully compatible with Google Consent Mode v2 and global privacy regulations.
View the App on ShopifyNew Prohibitions and Content Transparency: December 2026 and Beyond
Not all timelines were delayed. Some new prohibitions and transparency rules are arriving within months.
New prohibited AI practices (2 December 2026): For AI system providers, AI systems generating non-consensual intimate material are banned. Specifically, AI systems must not generate realistic intimate depictions without consent. Child sexual abuse material generation is prohibited by the AI Act. Prohibitions on non-consensual content take effect on December 2, 2026, and apply to AI systems intended to generate prohibited material. These additions were introduced through the AI Omnibus under the updated Article 5.
Transparency obligations (August–December 2026): Transparency rules for AI content take effect in August 2026. Implementing Article 50 transparency controls is crucial for organizations involved with customer-facing AI systems. AI-generated content must be identifiable by providers. Deepfakes must be clearly labeled under transparency rules. Transparency obligations apply to AI systems that generate synthetic content, including images, audio, video, and text, published on matters of public interest.
Transparency obligations for AI-generated content are delayed to December 2026 and are due by 2 December 2026 for systems already on the market before August 2026. This gives organizations a few extra months to implement content labeling workflows.
For e-commerce businesses using generative AI in marketing, product images, ad copy, and social media visuals, this means planning metadata schemes, user-facing disclaimers, and internal policies now. These obligations also intersect with duties under the Digital Services Act for online platforms.
Using Special Category Data for Bias Detection Under Article 4a
The AI Omnibus introduced Article 4a, creating a tightly controlled pathway for processing special category data, such as health, ethnicity, or religious beliefs, for bias detection and correction in AI systems.
Both providers and deployers of high-risk AI and certain AI systems outside the high-risk classification may process such sensitive data, but only when strictly necessary to identify and correct biases affecting health or safety risks, fundamental rights, or discrimination. This is not a free-for-all. Organizations must still comply with EU law and the GDPR: they need a valid legal basis, must apply data minimization, and must implement strong safeguards such as pseudonymization and access controls.
The necessity test is strict. Organizations must document why special category data is needed, demonstrate that no less intrusive method exists, and delete the data once bias detection is complete or the retention period expires. Conducting a DPIA is essential whenever special category data enters an AI workflow.
For e-commerce companies using AI for personalization, dynamic pricing, or fraud detection, controlled bias testing helps ensure AI systems do not indirectly discriminate against protected groups. Even if your recommendation engine seems low-risk, Article 4a’s safeguards matter if it processes data proxies for ethnicity or health conditions.
AI Governance as an Operational Discipline, Not Just Legal Review
The delayed implementation of the AI Act does not change the need for AI governance embedded across functions. Compliance depends on day-to-day operations: product teams classifying AI systems, procurement evaluating vendors, risk teams running impact assessments, and legal overseeing alignment with AI regulations.
General-purpose AI models used across HR, marketing, customer service, and analytics make AI governance a cross-functional challenge. AI systems built on the same provider’s foundation model can serve radically different purposes and carry different risk levels, depending on how they are deployed.
Practical examples of governance structures include:
- An AI steering committee with representatives from legal, engineering, product, and data teams
- Data protection officer involvement in AI risk assessments
- Engineering leads owning technical controls for human oversight and monitoring
- Procurement processes that include AI-specific vendor due diligence
Aligning AI governance with existing GDPR, cookie consent, and information-security programs reduces duplication. If your organization already maintains data controller obligations, privacy impact assessments, and consent tracking, you have a governance foundation that extends naturally to AI Act compliance.
Practical Preparation Roadmap: From Inventory to Documentation
Here is a concrete action plan for the next 12–24 months, accounting for the revised implementation timeline and compliance deadlines.
Step 1: Build and maintain an AI inventory. Organizations should build comprehensive AI inventories to classify risk tiers and compliance requirements. Catalog every AI system, internal and third-party, with attributes like purpose, data types (including special category data), interaction with individuals, and potential risk level.
Step 2: Classify by risk. Apply a step-by-step, risk-based approach: identify any systems that fall into high-risk AI categories under Annex I or Annex III, check against prohibited AI practices, and determine which transparency obligations apply. Map each system to specific business processes and data flows.
Step 3: Establish documentation templates early. Build reusable templates for risk management plans, technical documentation, data governance policies, human oversight instructions, andpost-markett monitoring records. These will be mandatory when high-risk obligations arrive in December 2027 and August 2028.
Step 4: Integrate AI checks into existing governance. Fold AI-related reviews into privacy impact assessments, vendor due diligence, and security reviews. AI Act compliance should become part of normal governance, not a separate project rushed before each deadline. Small mid-cap companies especially benefit from this integration, since dedicated AI compliance teams may not be feasible for them.
Step 5: Start AI literacy training. The AI literacy requirement is already enforceable. Build training modules that help staff recognize AI systems, understand their limitations, and escalate potential serious incidents.

Make Your Shopify Store GDPR & Cookie Compliant in Minutes
Start Free on ShopifyAligning with National and EU-Level Supervision & Future Guidance
EU-level rules and national AI governance frameworks will evolve in parallel. Organizations must prepare for both layers of oversight.
The AI Office supervises high-risk AI systems in the EU and has exclusive competence over GPAI models, including a growing governance role affecting major AI developers and platform providers. The AI Office’s supervisory role is significantly expanded under the Omnibus: it can impose substantial fines for non-compliance, conduct on-site inspections of AI systems, and oversee compliance with the AI Act’s obligations, including cases where the same provider controls both the GPAI model and the downstream system. It also supervises AI systems based on GPAI models operated by very large online platforms under the Digital Services Act, and providers must ensure AI-generated content is identifiable.
National competent authorities and market surveillance authorities will enforce the AI Act at the member state level. National AI regulatory sandboxes must be established by 2 August 2027, offering organizations a chance to test AI systems under supervisory guidance. The AI Office will also operate an EU-level sandbox for GPAI.
The European Commission and the European Parliament continue to shape the regulatory landscape through delegated acts, sectoral rules, and guidance documents. The AI Office is expected to publish further detail on high-risk classification, risk management expectations, enforcement mechanisms, and serious incident reporting throughout 2026–2028. Organizations should monitor these publications and build flexible governance frameworks that can absorb new guidance, including from national authorities like Spain’s Organic Law on AI governance, rather than hard-coding processes to today’s interpretation.
AI-enabled video games, certain medical AI, and AI used in critical infrastructure may face additional sectoral rules beyond the AI Act. The formal adoption of voluntary codes of practice (such as the GPAI Code of Practice) will also provide practical benchmarks once they receive final approval. Keep your governance adaptable, and you will not have to rebuild it every time the European Commission issues new guidance.
Conclusion
The EU AI Act timeline changes introduced by the AI Omnibus provide organizations with extended deadlines for high-risk AI system compliance while reinforcing immediate obligations such as AI literacy and prohibitions on certain practices. Businesses should use this additional time to build robust AI inventories, embed governance across teams, and prepare for evolving transparency and supervisory requirements. Staying proactive and aligned with both EU-level and national guidance will be key to successfully navigating this complex regulatory landscape


